CVE-2026-58442
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
Repository migration SSRF via multi-answer DNS allow-list bypass
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-918
Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
References (4)
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 88ee5874-cf24-4952-aea0-31affedb7ff2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Timeline
No history available yet.